All of lore.kernel.org
 help / color / mirror / Atom feed
From: srinivas pandruvada <srinivas.pandruvada@linux.intel.com>
To: Yibo Tan <lhfff@tju.edu.cn>, Jiri Kosina <jikos@kernel.org>,
	Jonathan Cameron <jic23@kernel.org>,
	Benjamin Tissoires <bentiss@kernel.org>
Cc: Zhang Lixu <lixu.zhang@intel.com>,
	Andy Shevchenko <andriy.shevchenko@intel.com>,
	linux-input@vger.kernel.org,  linux-iio@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v1] HID: sensor-hub: synchronize multi-value read cancellation
Date: Thu, 10 Sep 2026 11:28:32 -0700	[thread overview]
Message-ID: <9ae8e6b44ffaf5affb7324f802a3626c581ac461.camel@linux.intel.com> (raw)
In-Reply-To: <20260910112338.4171983-1-lhfff@tju.edu.cn>

On Thu, 2026-09-10 at 19:23 +0800, Yibo Tan wrote:
> sensor_hub_input_attr_read_values() publishes a caller-owned buffer
> to the
> raw-event path. If its interruptible wait times out or is
> interrupted, it
> clears pending.status without taking data->lock and returns.
> 

Hi Lixu,

Please give me quick test. Change itself looks good, not sure if we
need something more.

Thanks,
Srinivas


> sensor_hub_raw_event() may already have observed pending.status while
> holding that lock. The caller can then release its buffer before raw-
> event
> finishes copying into it.
> 
> Take data->lock when cancelling the request. The raw-event path now
> either
> sees the request retired or finishes the copy before cancellation can
> return.
> 
> On an uninstrumented PREEMPT_RT kernel, a valid 16-byte quaternion
> report
> overwrote a live futex waiter's plist node with the report's 0x41
> payload.
> Two vulnerable runs produced the same general protection fault in
> plist_del(), after 471 and 91 completed trials. The locking fix
> completed
> two 10,000-trial runs without an Oops, panic, warning or payload
> signature.
> 
> The virtual provider setup and FIFO assignment require privilege. The
> IIO
> read, signal handling and futex operations run as uid 65534 without
> effective capabilities. No physical-device or normal-priority hit was
> tested.
> 
> A source reproducer, kernel configuration, complete serial logs and
> the
> vulnerable/fixed result table are available at:
> 
> https://github.com/kimaiden1984-boop/linux-kernel-poc-collections/tree/main/cases/hid-sensor-quaternion-root-a
> 
> Fixes: f784fcea4506 ("HID: sensor-hub: Add
> sensor_hub_input_attr_read_values() for multi-byte reads")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Link:
> https://lore.kernel.org/r/20260610083849.067A11F00893@smtp.kernel.org/
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:GPT-5
> Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
> ---
>  drivers/hid/hid-sensor-hub.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/hid/hid-sensor-hub.c b/drivers/hid/hid-sensor-
> hub.c
> index 6470a290ebfc..80f18aff6f1f 100644
> --- a/drivers/hid/hid-sensor-hub.c
> +++ b/drivers/hid/hid-sensor-hub.c
> @@ -335,7 +335,9 @@ int sensor_hub_input_attr_read_values(struct
> hid_sensor_hub_device *hsdev,
>  		else if (cycles < 0)
>  			ret = cycles;
>  
> +		spin_lock_irqsave(&data->lock, flags);
>  		hsdev->pending.status = false;
> +		spin_unlock_irqrestore(&data->lock, flags);
>  	}
>  	mutex_unlock(hsdev->mutex_ptr);
>  

  parent reply	other threads:[~2026-09-10 18:28 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10 11:23 [PATCH v1] HID: sensor-hub: synchronize multi-value read cancellation Yibo Tan
2026-09-10 11:35 ` sashiko-bot
2026-09-10 15:32 ` Andy Shevchenko
2026-09-10 18:28 ` srinivas pandruvada [this message]
2026-09-11  5:16   ` Zhang, Lixu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9ae8e6b44ffaf5affb7324f802a3626c581ac461.camel@linux.intel.com \
    --to=srinivas.pandruvada@linux.intel.com \
    --cc=andriy.shevchenko@intel.com \
    --cc=bentiss@kernel.org \
    --cc=jic23@kernel.org \
    --cc=jikos@kernel.org \
    --cc=lhfff@tju.edu.cn \
    --cc=linux-iio@vger.kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lixu.zhang@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.